mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
docs: Strengthen keys note (#46578)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Consolidated API key deprecation guidance into a reusable notice for consistent messaging across docs. Announces deprecation of legacy anon/service_role JWT-secret keys by end of 2026, instructs switching to sb_publishable_xxx / sb_secret_xxx, and provides steps to locate and copy both new and legacy keys. Applied across auth, getting-started, API, and realtime guides. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: fadymak <dev@fadymak.com>
This commit is contained in:
1 parent
4ed75886fc
commit
e4f824b835
10 files changed
+24
-75
No files matched your search
@@ -338,7 +338,7 @@ export const gettingstarted: NavMenuConstant = {
|
||||
items: [
|
||||
{ name: 'Build with AI tools', url: '/guides/ai-tools' },
|
||||
{ name: 'API Keys', url: '/guides/getting-started/api-keys' },
|
||||
{ name: 'Local Development', url: '/guides/cli/getting-started' },
|
||||
{ name: 'Local Development', url: '/guides/local-development/cli/getting-started' },
|
||||
{ name: 'Architecture', url: '/guides/getting-started/architecture' },
|
||||
{
|
||||
name: 'Migrating to new API keys',
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
<Admonition type="deprecation" title="Changes to API keys">
|
||||
|
||||
Supabase has changed the way keys work to improve project security and developer experience. You can [read the full announcement on GitHub](https://github.com/orgs/supabase/discussions/29260).
|
||||
|
||||
**They will be deprecated by the end of 2026, and you should now use the publishable (`sb_publishable_xxx`) and secret (`sb_secret_xxx`) keys instead**.
|
||||
|
||||
In most cases, you can get keys from [the Project's **Connect** dialog](/dashboard/project/\_?showConnect=true&connectTab={{ .tab }}&framework={{ .framework }}), but if you want a specific key, you can find them in the [**Settings > API Keys**](/dashboard/project/_/settings/api-keys/) section of the Dashboard.
|
||||
|
||||
- **For new keys**, open the **API Keys** tab, if you don't have a publishable key already, click **Create new API Keys**, and copy the value from the **Publishable key** section for client-side operations. For server-side operations, copy the value from the **Secret keys** section.
|
||||
- **For legacy keys**, copy the `anon` key for client-side operations and the `service_role` key for server-side operations from the **Legacy API Keys** tab.
|
||||
|
||||
</Admonition>
|
||||
@@ -6,15 +6,5 @@ To do this, you need to get the Project URL and key from [the project **Connect*
|
||||
|
||||
[Read the API keys docs](/docs/guides/getting-started/api-keys) for a full explanation of all key types and their uses.
|
||||
|
||||
<Admonition type="note" title="Changes to API keys">
|
||||
|
||||
Supabase is changing the way keys work to improve project security and developer experience. You can [read the full announcement on GitHub](https://github.com/orgs/supabase/discussions/29260).
|
||||
|
||||
The older `anon` and `service_role` keys will work until the end of 2026 but **we strongly encourage switching to and using** the new publishable (`sb_publishable_xxx`) and secret (`sb_secret_xxx`) keys now.
|
||||
|
||||
In most cases, you can get keys from [the Project's **Connect** dialog](/dashboard/project/\_?showConnect=true&connectTab={{ .tab }}&framework={{ .framework }}), but if you want a specific key, you can find them in the [**Settings > API Keys**](/dashboard/project/_/settings/api-keys/) section of the Dashboard.
|
||||
|
||||
- **For legacy keys**, copy the `anon` key for client-side operations and the `service_role` key for server-side operations from the **Legacy API Keys** tab.
|
||||
- **For new keys**, open the **API Keys** tab, if you don't have a publishable key already, click **Create new API Keys**, and copy the value from the **Publishable key** section.
|
||||
|
||||
</Admonition>
|
||||
<$Partial path="api_keys_deprecation.mdx" variables={{ "framework": "{{ .framework }}", "tab": "{{ .tab }}" }}
|
||||
/>
|
||||
@@ -8,15 +8,5 @@ To do this, you need to get the Project URL and key from [the project **Connect*
|
||||
|
||||
[Read the API keys docs](/docs/guides/getting-started/api-keys) for a full explanation of all key types and their uses.
|
||||
|
||||
<Admonition type="note" title="Changes to API keys">
|
||||
|
||||
Supabase is changing the way keys work to improve project security and developer experience. You can [read the full announcement on GitHub](https://github.com/orgs/supabase/discussions/29260).
|
||||
|
||||
The older `anon` and `service_role` keys will work until the end of 2026 but **we strongly encourage switching to and using** the new publishable (`sb_publishable_xxx`) and secret (`sb_secret_xxx`) keys now.
|
||||
|
||||
In most cases, you can get keys from [the Project's **Connect** dialog](/dashboard/project/\_?showConnect=true&connectTab={{ .tab }}&framework={{ .framework }}), but if you want a specific key, you can find them in the [**Settings > API Keys**](/dashboard/project/_/settings/api-keys/) section of the Dashboard.
|
||||
|
||||
- **For legacy keys**, copy the `anon` key for client-side operations and the `service_role` key for server-side operations from the **Legacy API Keys** tab.
|
||||
- **For new keys**, open the **API Keys** tab, if you don't have a publishable key already, click **Create new API Keys**, and copy the value from the **Publishable key** section.
|
||||
|
||||
</Admonition>
|
||||
<$Partial path="api_keys_deprecation.mdx" variables={{ "framework": "{{ .framework }}", "tab": "{{ .tab }}" }}
|
||||
/>
|
||||
@@ -66,16 +66,7 @@ Every Supabase project has a unique API URL. Your API is secured behind an API g
|
||||
|
||||
To do this, you need to get the Project URL and key from [the project's **Connect** dialog](/dashboard/project/_?showConnect=true).
|
||||
|
||||
<Admonition type="note" title="Changes to API keys">
|
||||
|
||||
Supabase is changing the way keys work to improve project security and developer experience. You can [read the full announcement](https://github.com/orgs/supabase/discussions/29260), but in the transition period, you can use both the current `anon` and `service_role` keys and the new publishable key with the form `sb_publishable_xxx` which will replace the older keys.
|
||||
|
||||
In most cases, you can get the correct key from [the Project's **Connect** dialog](/dashboard/project/_?showConnect=true), but if you want a specific key, you can find all keys in [the API Keys section of a Project's Settings page](/dashboard/project/_/settings/api-keys/):
|
||||
|
||||
- **For legacy keys**, copy the `anon` key for client-side operations and the `service_role` key for server-side operations from the **Legacy API Keys** tab.
|
||||
- **For new keys**, open the **API Keys** tab, if you don't have a publishable key already, click **Create new API Keys**, and copy the value from the **Publishable key** section.
|
||||
|
||||
</Admonition>
|
||||
<$Partial path="api_keys_deprecation.mdx" variables={{ "framework": "{{ .framework }}", "tab": "{{ .tab }}" }} />
|
||||
|
||||
[Read the API keys docs](/docs/guides/getting-started/api-keys) for a full explanation of all key types and their uses.
|
||||
|
||||
|
||||
@@ -68,8 +68,6 @@ hideToc: true
|
||||
<ProjectConfigVariables variable="url" />
|
||||
<ProjectConfigVariables variable="publishable" />
|
||||
|
||||
|
||||
|
||||
</StepHikeCompact.Details>
|
||||
|
||||
<StepHikeCompact.Code>
|
||||
|
||||
@@ -32,15 +32,7 @@ There are 4 types of API keys that you can use with Supabase:
|
||||
| <span className="whitespace-nowrap!">`anon`</span> | JWT (long lived) | Low | <span className="whitespace-nowrap!">Platform, CLI</span> | Legacy version of publishable keys. |
|
||||
| <span className="whitespace-nowrap!">`service_role`</span> | JWT (long lived) | Elevated | <span className="whitespace-nowrap!">Platform, CLI</span> | Legacy version of secret keys. |
|
||||
|
||||
<Admonition type="caution" title="Changes to API keys">
|
||||
|
||||
Supabase has changed the way keys work to improve project security and developer experience. You can read [the full announcement](https://github.com/orgs/supabase/discussions/29260).
|
||||
|
||||
`anon` and `service_role` keys are based on the project's JWT secret. They are generated when your project is created and you can only change them when you rotate the JWT secret. This can cause significant issues in production applications. **You should now use the `sb_publishable_xxx` and `sb_secret_xxx` keys instead**. See [Migrate to publishable and secret API keys](/docs/guides/getting-started/migrating-to-new-api-keys) for a step-by-step guide.
|
||||
|
||||
You can still find legacy keys in the **Legacy anon, service_role API keys** tab of the [**Settings > API Keys**](/dashboard/project/_/settings/api-keys/) section of the Dashboard:
|
||||
|
||||
</Admonition>
|
||||
<$Partial path="api_keys_deprecation.mdx" />
|
||||
|
||||
## Publishable keys
|
||||
|
||||
|
||||
@@ -4,16 +4,10 @@ title: 'Migrating to publishable and secret API keys'
|
||||
description: 'Move from legacy JWT-based anon and service_role keys to publishable and secret keys.'
|
||||
---
|
||||
|
||||
Supabase has changed the way API keys work. The legacy `anon` and `service_role` keys are based on your project's JWT secret, which makes them hard to rotate without downtime. The new publishable (`sb_publishable_...`) and secret (`sb_secret_...`) keys can be created, named, and revoked independently, so you can rotate a single key without touching the rest of your app.
|
||||
<$Partial path="api_keys_deprecation.mdx" />
|
||||
|
||||
This guide covers migrating an **existing project.** Both key types work simultaneously, so you can swap clients one at a time and deactivate the legacy keys only after nothing depends on them.
|
||||
|
||||
<Admonition type="note">
|
||||
|
||||
The legacy `anon` and `service_role` keys keep working until the end of 2026. You don't have to migrate today, but doing it early lets you rotate keys safely from now on.
|
||||
|
||||
</Admonition>
|
||||
|
||||
## Before you start
|
||||
|
||||
The migration maps onto your existing keys:
|
||||
|
||||
@@ -37,17 +37,8 @@ You can use the Supabase client libraries to receive Broadcast messages.
|
||||
|
||||
Get the Project URL and key from [the project's **Connect** dialog](/dashboard/project/_?showConnect=true).
|
||||
|
||||
<Admonition type="note" title="Changes to API keys">
|
||||
|
||||
Supabase is changing the way keys work to improve project security and developer experience. You can [read the full announcement](https://github.com/orgs/supabase/discussions/29260), but in the transition period, you can use both the current `anon` and `service_role` keys and the new publishable key with the form `sb_publishable_xxx` which will replace the older keys.
|
||||
|
||||
**The legacy keys will be deprecated shortly, so we strongly encourage switching to and using the new publishable and secret API keys**.
|
||||
|
||||
In most cases, you can get the correct key from [the Project's **Connect** dialog](/dashboard/project/_?showConnect=true), but if you want a specific key, you can find all keys in [the API Keys section of a Project's Settings page](/dashboard/project/_/settings/api-keys/):
|
||||
|
||||
**For new keys**, open the **API Keys** tab, if you don't have a publishable key already, click **Create new API Keys**, and copy the value from the **Publishable key** section.
|
||||
|
||||
</Admonition>
|
||||
<$Partial path="api_keys_deprecation.mdx" variables={{ "framework": "{{ .framework }}", "tab": "{{ .tab }}" }}
|
||||
/>
|
||||
|
||||
<Tabs
|
||||
scrollable
|
||||
|
||||
@@ -47,17 +47,8 @@ The complete presence state returned by `presenceState()` looks like this:
|
||||
|
||||
Get the Project URL and key from [the project's **Connect** dialog](/dashboard/project/_?showConnect=true).
|
||||
|
||||
<Admonition type="note" title="Changes to API keys">
|
||||
|
||||
Supabase is changing the way keys work to improve project security and developer experience. You can [read the full announcement](https://github.com/orgs/supabase/discussions/29260), but in the transition period, you can use both the current `anon` and `service_role` keys and the new publishable key with the form `sb_publishable_xxx` which will replace the older keys.
|
||||
|
||||
**The legacy keys will be deprecated shortly, so we strongly encourage switching to and using the new publishable and secret API keys**.
|
||||
|
||||
In most cases, you can get the correct key from [the Project's **Connect** dialog](/dashboard/project/_?showConnect=true), but if you want a specific key, you can find all keys in [the API Keys section of a Project's Settings page](/dashboard/project/_/settings/api-keys/):
|
||||
|
||||
**For new keys**, open the **API Keys** tab, if you don't have a publishable key already, click **Create new API Keys**, and copy the value from the **Publishable key** section.
|
||||
|
||||
</Admonition>
|
||||
<$Partial path="api_keys_deprecation.mdx" variables={{ "framework": "{{ .framework }}", "tab": "{{ .tab }}" }}
|
||||
/>
|
||||
|
||||
<Tabs
|
||||
scrollable
|
||||
|
||||
Reference in new issue
Block a user